Security & data
How CargoRoute handles your company's data.
This page describes the CargoRoute application as it is built today. It says what we do, and it says plainly what we do not claim. It is a description, not a contract: the Terms are.
Your data is yours
The loads, customers, drivers, documents and financial records your company enters belong to your company. We use them to run the service for you and for nothing else: we do not sell them, and we do not use them for advertising.
Signing in
Each person signs in with their own email address and password. Passwords are stored only as a one-way hash, never in readable form. A session is kept in cookies that page scripts cannot read and that are sent only over HTTPS.
Two-factor sign-in is not available yet.
Who can see what
Every person in a workspace has one of five roles: Owner, Manager, Dispatcher, Accounting or Driver. A person sees only the pages and records that role allows. A driver sees their own loads, never customer rates and never another driver's work. A dispatcher books and assigns loads without seeing customer rates, invoices or settlements.
These rules are enforced on the server and in the database itself, row by row, not just hidden on the screen. One company's records are separated from every other company's in the same way.
Documents and files
Uploaded files, such as PODs, BOLs, CDLs, receipts and incident photos, are kept in private storage. A file has no public address: each time one is opened, a signed-in person whose role allows it is given a link that expires after one minute.
Uploads are limited to PDF, JPEG and PNG files, and a file's contents are checked against the type it claims to be.
A record of changes
Changes to records are logged with who made them and when. Owners and Managers can read the audit log; nobody in a workspace can edit or delete it. Imports and CSV exports are logged too.
In transit
Every page and every request is served over encrypted HTTPS, and browsers are told to refuse plain HTTP for the domain. Both this website and the application send headers that stop other sites from framing them and limit what a page may load.
Where it runs
The application runs on third-party cloud services: a hosting platform for the application, and a managed PostgreSQL database and file storage for the data. Invitations and reminders are sent through an email delivery provider. Ask us and we will tell you which providers we use.
Two outside services are asked for public information. Weather on a load comes from the US National Weather Service, which is sent the coordinates of a stop. Filling in a city from a ZIP code sends that ZIP code to a postal code lookup service. Neither is sent anything else about your company.
The application loads no analytics, advertising or tracking scripts.
Export and deletion
The main lists can be exported as CSV files by anyone whose role allows it: loads, customers, drivers, trucks, trailers, invoices, expenses, settlements, fuel and tolls.
Business records are archived rather than erased, so a load's history stays intact. An Owner or Manager can permanently delete an uploaded document, except issued invoice and settlement PDFs.
There is no one-click export of everything and no self-service account deletion yet. If you need either, write to support@cargoroutetms.com.
What we do not claim
- No security certification. CargoRoute has no SOC 2 report and no ISO 27001 certificate.
- No published backup or availability commitment. We do not publish a backup schedule, a recovery time or an availability figure yet. Ask us where this stands before you rely on it.
- No two-factor sign-in yet, as said above.
- No regulatory certification. Compliance tracking is a record of expiration dates with warnings. It does not certify that a driver or a unit is compliant.
- No payment processing. CargoRoute records payments that have already been made. It moves no money and has no fields for full card or bank account numbers.
Reporting a problem
If you believe you have found a security problem, write to support@cargoroutetms.com. A person reads it.
Last updated October 5, 2026.